Bug 1173555 (CVE-2014-7824)
Summary: | CVE-2014-7824 dbus: local denial of service via incomplete fix for CVE-2014-3636 | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Vasyl Kaigorodov <vkaigoro> | ||||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||||
Status: | CLOSED NOTABUG | QA Contact: | |||||||
Severity: | low | Docs Contact: | |||||||
Priority: | low | ||||||||
Version: | unspecified | CC: | amigadave, dking, drizt72, erik-fedora, jrusnack, lpoetter, slawomir, walters | ||||||
Target Milestone: | --- | Keywords: | Security | ||||||
Target Release: | --- | ||||||||
Hardware: | All | ||||||||
OS: | Linux | ||||||||
Whiteboard: | |||||||||
Fixed In Version: | dbus 1.6.26, dbus 1.8.10, dbus 1.9.2 | Doc Type: | Bug Fix | ||||||
Doc Text: | Story Points: | --- | |||||||
Clone Of: | Environment: | ||||||||
Last Closed: | 2014-12-12 23:32:21 UTC | Type: | --- | ||||||
Regression: | --- | Mount Type: | --- | ||||||
Documentation: | --- | CRM: | |||||||
Verified Versions: | Category: | --- | |||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||
Embargoed: | |||||||||
Bug Depends On: | 1173556, 1173557, 1173558 | ||||||||
Bug Blocks: | 1140534, 1160627 | ||||||||
Attachments: |
|
Description
Vasyl Kaigorodov
2014-12-12 12:12:07 UTC
Created dbus tracking bugs for this issue: Affects: fedora-all [bug 1173556] Created mingw-dbus tracking bugs for this issue: Affects: fedora-all [bug 1173557] Affects: epel-7 [bug 1173558] Created attachment 967617 [details]
0001-DBusSystemLogSeverity-add-DBUS_SYSTEM_LOG_WARNING.patch
Created attachment 967618 [details]
0002-Set-fd-rlimit-to-64k-for-the-system-dbus-daemon.patch
Original report to oss-security: http://www.openwall.com/lists/oss-security/2014/11/10/2 Note that CVE-2014-3636 (bug #1140525) was not previously corrected by any errata. As no prior Red Hat Enterprise Linux release contains the incorrect fix, they are not affected by this particular CVE. See bug #1140525 for details. dbus-1.6.28-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report. dbus-1.8.12-1.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report. dbus-1.6.28-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report. |